- Distribution Method : Unknown
- MD5 : b99b7516b408b9ca3644727e63d0c68d
- Major Detection Name : Ransom:MSIL/Kelnoc.A (Microsoft), Ransom.HiddenTear!g1 (Norton)
- Encrypted File Pattern : .evil
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_YOUR_FILES.HTML
- C:\Users\%UserName%\AppData\Roaming\delback.bat
- Payment Instruction File : DECRYPT_YOUR_FILES.HTML
- Major Characteristics :
- Offline Encryption
- Hidden-Tear Open Source based Ransomware
- Disable system restore (vssadmin delete shadows /all /quiet)
List